EU compliance

Sovereign by architecture, not by claim.

Local-first means compliance is the default state, not a configuration you have to keep maintaining. We're a Dutch company building on European infrastructure with European primary providers. The EU AI Act isn't something we adapt to, it's the frame we designed inside.

01 / 05

Data stays on your machine

Local mode means prompts, completions, agent memory, and capability data never leave the device. The cloud is opt-in per prompt and per model, not a global setting buried in the defaults.

02 / 05

No US CLOUD Act exposure

Atypisch is registered in the Netherlands. Soriku Cloud runs on European infrastructure (Nefos in the EU region). Mistral is the recommended remote primary. US providers are available too, by your choice and with your own key.

03 / 05

EU AI Act, designed-in

Transparency, traceability, human oversight, and risk-tier handling are part of the engine, not bolted on afterwards. Every routed prompt has provenance, so you see which model answered and why. Enterprise includes formal compliance support.

04 / 05

GDPR by default

Local mode means prompts, completions, and agent memory stay on your machine, so for most work there is no third-party processing to account for. When you do use the cloud it is opt-in per prompt, with data-subject rights, retention, and breach handling written down rather than assumed.

05 / 05

API keys never leave your machine

In hosted Soriku Cloud, your remote-provider keys live encrypted in your workspace. They're decrypted at request time, used, then dropped. No long-term server-side storage of your credentials.

Procurement

What you can put in a procurement form

Read the details in the docs: GDPR · EU AI Act · DPA

Need a DPA or vendor assessment?

Enterprise customers get formal compliance support, including AI Act risk-tier documentation tailored to your use case.

Contact compliance